Auto disable RSASHA1 and NSEC3RSASHA1 when not supported by the OS
The is a minimal change so that named can run on Oracle Linux 9
and RHEL9
with default crypto policy.
Primary zones using RSASHA1 and NSEC3RSASHA1 for signing need to be migrated off of those algorithms before upgrading/using Oracle Linux 9
and RHEL9
.
Zones solely using RSASHA1
and NSEC3RSASHA1
will validate as insecure.
Edited by Mark Andrews